Total
45383 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-48949 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of validation leads to an XSS vulnerability in the MFA management views. | |||||
| CVE-2026-48950 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | |||||
| CVE-2026-48951 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | |||||
| CVE-2026-48952 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | |||||
| CVE-2026-48953 | 1 Joomla | 1 Joomla\! | 2026-07-09 | N/A | 6.1 MEDIUM |
| Lack of escaping leads to an XSS vulnerability in the generic image output layout. | |||||
| CVE-2025-8591 | 1 Wso2 | 8 Api Control Plane, Api Manager, Identity Server and 5 more | 2026-07-09 | N/A | 6.1 MEDIUM |
| The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking. | |||||
| CVE-2026-8315 | 2026-07-09 | N/A | 5.4 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |||||
| CVE-2026-8310 | 2026-07-09 | N/A | 6.1 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |||||
| CVE-2026-56809 | 2026-07-09 | N/A | 6.1 MEDIUM | ||
| Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL. | |||||
| CVE-2024-37859 | 1 Oretnom23 | 1 Lost And Found Information System | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php. | |||||
| CVE-2024-37856 | 1 Oretnom23 | 1 Lost And Found Information System | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page. | |||||
| CVE-2024-37675 | 1 Tessi | 1 Docubase | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the parameter "sectionContent" related to the functionality of adding notes to an uploaded file. | |||||
| CVE-2024-37674 | 1 Moodle | 1 Moodle | 2026-07-09 | N/A | 5.5 MEDIUM |
| Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity. | |||||
| CVE-2024-37673 | 1 Tessi | 1 Docubase | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter. | |||||
| CVE-2024-37672 | 1 Tessi | 1 Docubase | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter. | |||||
| CVE-2024-37671 | 1 Tessi | 1 Docubase | 2026-07-09 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter. | |||||
| CVE-2024-32409 | 1 Sem-cms | 1 Semcms | 2026-07-09 | N/A | 7.1 HIGH |
| An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. | |||||
| CVE-2024-32206 | 1 Wuzhicms | 1 Wuzhicms | 2026-07-09 | N/A | 4.6 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter. | |||||
| CVE-2024-31064 | 1 Munyweki | 1 Insurance Management System | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field. | |||||
| CVE-2024-29644 | 1 Dcatadmin | 1 Dcat Admin | 2026-07-09 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box. | |||||
